CVE-2019-1907

CWE-2854 documents4 sources
Severity
8.8HIGH
EPSS
0.1%
top 64.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21
Latest updateMay 24

Description

A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected software. A successful exploit could allow the attacker with read-only privileges t

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-34x5-95ff-w3cg: A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive confi2022-05-24
CVEList
Cisco Integrated Management Controller Substring Comparison Privilege Escalation Vulnerability2019-08-21

📋Vendor Advisories

1
Cisco
Cisco Integrated Management Controller Substring Comparison Privilege Escalation Vulnerability2019-08-21